- Jurisdiction
- Poland / European Union
- Version
- 2026-07-03
- Operator
- Nova Group Sp. z o.o.
This Cookies Policy explains how eVisa Immigration, operated by Nova Group Sp. z o.o., uses cookies, local storage, pixels, SDKs, tags, and similar technologies on https://evisa-immigration.com and related online services.
1. What cookies and similar technologies are
Cookies are small files stored on a user’s device. Similar technologies include local storage, session storage, pixels, SDKs, tags, consent signals, and device or browser identifiers. They may be used to keep the website working, remember consent choices, authenticate users, secure payments, prevent fraud, measure performance, understand use of the service, and support advertising.
2. Categories of technologies we use
We may use the following categories:
- Essential cookies and storage: required for website operation, security, checkout, account login, fraud prevention, consent management, and service delivery.
- Analytics cookies and storage: used to understand website and app performance, page usage, conversion funnels, errors, and customer experience.
- Marketing cookies and pixels: used for advertising measurement, remarketing, conversion tracking, campaign attribution, and ad personalization where consent is given.
- Authentication cookies: used to keep users signed in and protect accounts.
- Payment and security cookies: used by payment processors and fraud-prevention tools to process payments and protect against abuse.
3. Consent mechanism
The website may use Cookiebot CMP to collect, store, and manage cookie consent choices. Google Consent Mode v2 may be used to communicate consent choices to Google services. Where consent is required, analytics and marketing technologies are activated according to the consent choices recorded by the consent banner or cookie settings widget.
You can change or withdraw your cookie consent at any time by reopening the cookie settings widget available on the website.
Some essential, payment-security, fraud-prevention, account, and consent-management technologies are necessary for the service and may operate without optional consent where permitted by law.
4. Google Consent Mode v2
Google Consent Mode v2 allows Google tags to adjust behavior based on consent choices. Consent signals may include:
- analytics_storage: analytics storage.
- ad_storage: advertising storage.
- ad_user_data: sending user data related to advertising to Google.
- ad_personalization: personalized advertising.
Where a user denies consent, Google tags may be limited, blocked, or run in a consent-aware mode depending on the configuration.
5. Cookie and storage table
The following table describes cookies and similar technologies that may be used on the website. Actual cookies may vary depending on country, browser, device, user choices, payment method, app state, and website configuration.
| Provider | Cookie/local storage name or pattern | Category | Purpose | Typical retention | Consent required | Notes |
|---|---|---|---|---|---|---|
| Cookiebot CMP | CookieConsent | Essential | Stores the user’s cookie-consent choices and consent categories | 12 months | No | Required to remember consent status and operate the consent mechanism |
| Cookiebot CMP | CookiebotConsent, CookiebotBulkConsent, cookiebot-* | Essential | Consent logging, region handling, and consent-state management | Session to 12 months | No | Names may vary by Cookiebot configuration |
| Google Consent Mode v2 | gtag consent state, consent signals | Essential / consent signaling | Communicates consent choices to Google tags for analytics and advertising behavior | Session to 13 months depending on implementation | No for consent signal; Yes for optional analytics or marketing storage | Consent signals are not always cookies but may interact with Google tags |
| Google Analytics 4 | _ga | Analytics | Distinguishes users for analytics and site-measurement purposes | 24 months | Yes where required | Used only according to consent settings where required |
| Google Analytics 4 | _ga_* | Analytics | Persists GA4 session state for a specific measurement ID | 24 months | Yes where required | The suffix varies by GA4 property or stream |
| Google Analytics / Tag Manager | _gid, _gat, _dc_gtm_* | Analytics | Session attribution, request throttling, and tag-management support where configured | 1 minute to 24 hours | Yes where required | These may appear depending on configuration |
| Google Ads / Conversion Linker | _gcl_au | Marketing | Stores ad-click and conversion-linking information for conversion measurement | 90 days | Yes | Used for Google Ads conversion tracking and attribution |
| Google Ads | _gcl_aw, _gcl_dc, _gcl_gb | Marketing | Stores Google click identifiers and campaign attribution information | 90 days | Yes | Names vary by Google Ads and Floodlight configuration |
| Google advertising products | IDE, ANID, NID, DV, test_cookie, DSID | Marketing / third-party | Advertising delivery, frequency capping, remarketing, fraud prevention, and ad measurement | Session to 13 months, sometimes up to 24 months depending on Google settings | Yes where required | May be set on Google or DoubleClick domains |
| Plausible Analytics | No default persistent cookie | Analytics | Privacy-friendly aggregate analytics without default cookie storage | Not applicable | Usually no, unless configured with cookies or personal data | Plausible is usually cookieless unless configured otherwise |
| PostHog | ph_*_posthog | Analytics / product analytics | Product analytics, feature flags, session identifiers, device identifiers, and funnel analysis | 12 months | Yes where required | PostHog may use cookies and local storage depending on configuration |
| PostHog | posthog, posthog_*, ph_* local storage | Analytics / product analytics | Stores analytics configuration, distinct ID, session ID, feature flags, and product usage state | 12 months | Yes where required | Storage may use cookies, local storage, or both |
| Clerk | __session | Authentication | Stores session token information needed for account login and session continuity | Session to configured session lifetime | No | Required for account authentication and cannot be disabled when account features are used |
| Clerk | clerk_*, __client_uat, __clerk_db_jwt, __clerk_handshake | Authentication / security | Account session management, login state, anti-abuse, and authentication flows | Session to 12 months depending on configuration | No | Names may vary by Clerk setup, browser, and domain configuration |
| Stripe | __stripe_mid | Payment / security | Fraud prevention, payment security, device recognition, and transaction-risk monitoring | 12 months | No where necessary for payment security | Set by Stripe.js or Stripe checkout/payment flows |
| Stripe | __stripe_sid | Payment / security | Short-term session identifier for payment security and fraud prevention | 30 minutes to session | No where necessary for payment security | Used during checkout and payment flows |
| Stripe | m, pay_sid, __Host-LinkSession, stripe_*, __stripe_* | Payment / security | Payment authentication, checkout sessions, fraud prevention, and secure payment processing | Session to 12 months | No where necessary for payment security | Exact names vary by Stripe product and checkout configuration |
| Worldline | Worldline payment session cookies | Payment / security | Payment-session handling, payment authentication, fraud prevention, transaction continuity | Session to 90 days | No where necessary for payment security | Exact names vary by Worldline integration, region, and payment method |
| Worldline | Worldline fraud-prevention identifiers | Payment / security | Device, browser, transaction-risk, and fraud-prevention checks | Session to 6 months | No where necessary for payment security | Used only where Worldline or related payment methods are active |
| eVisa Immigration | session, csrf, auth, account, checkout, cart, language, currency, consent, security, rate-limit patterns | Essential | Session continuity, security, checkout flow, localization, anti-abuse, and service functionality | Session to 12 months | No | Names depend on website implementation |
| eVisa Immigration | referral, campaign, landing, source, utm, affiliate patterns | Analytics / marketing | Measures campaign source, partner attribution, and conversion path | Session to 90 days | Yes where required | May be stored in cookies or local storage |
| Support and communication tools | support_*, chat_*, messenger_*, intercom_*, help_* | Essential / analytics / marketing depending on use | Customer support chat, support history, routing, and service communication | Session to 13 months | Depends on category | Optional marketing or analytics features require consent where required |
| App and mobile SDKs | app_session, device, push, install, attribution patterns | Essential / analytics / marketing depending on use | App login, app security, push notifications, install attribution, and app analytics | Session to 24 months | Depends on category | App stores and mobile operating systems may apply additional rules |
6. Essential cookies
Essential cookies and storage are required for core website and service functions. They may support account login, checkout, payment security, fraud prevention, consent management, document upload, language and currency settings, order continuity, form security, and abuse prevention. Without them, the website or service may not function properly.
7. Analytics cookies
Analytics technologies help us understand how users interact with the website and service. This may include page views, conversion funnels, form completion, errors, performance, and product usage. Analytics tools may include GA4 / Google Analytics 4, Plausible Analytics, PostHog, and related event-measurement tools.
Where required, analytics cookies and analytics storage are used only after consent.
8. Marketing cookies
Marketing technologies may be used for Google Ads conversion tracking, Google Ads remarketing, campaign attribution, ad performance measurement, and personalized advertising where permitted. These technologies may process ad-click identifiers, conversion events, hashed customer data where configured and permitted, and remarketing audience information.
Marketing cookies and marketing storage require consent where required by law.
9. Authentication cookies
Authentication cookies are used to sign users in, keep sessions active, protect accounts, and prevent unauthorized access. Clerk or similar providers may set cookies required for account functionality. If a user disables authentication cookies, account features may not work.
10. Payment and security cookies
Stripe, Worldline, card networks, banks, and related payment providers may use cookies or similar technologies for payment authentication, fraud prevention, transaction security, dispute handling, and payment-session continuity. These technologies help protect customers and the business and are generally treated as necessary for checkout where payment functionality is used.
11. Third-party cookies
Some technologies may be set by third-party domains, such as Google, Stripe, Worldline, Clerk, Cookiebot, analytics providers, advertising providers, app stores, or support tools. Third-party providers may process data under their own privacy policies and technical configurations.
12. Managing cookies in the browser
Users can also manage cookies through browser settings. Blocking all cookies may affect account login, checkout, payments, document upload, consent storage, and customer-support functionality.
13. Updates to this Policy
We may update this Cookies Policy when technologies, providers, cookie names, retention periods, consent mechanisms, or legal requirements change. The latest version will be available on the website.